All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ming Lei <ming.lei@redhat.com>
To: Jens Axboe <axboe@kernel.dk>
Cc: linux-block@vger.kernel.org, Bart Van Assche <bvanassche@acm.org>,
	Christoph Hellwig <hch@lst.de>,
	John Garry <john.garry@huawei.com>,
	"Blank-Burian, Markus, Dr." <blankburian@uni-muenster.de>
Subject: Re: [PATCH] blk-mq: fix kernel panic during iterating over flush request
Date: Tue, 17 Aug 2021 08:58:59 +0800	[thread overview]
Message-ID: <YRsJ00t5XDdlebcW@T590> (raw)
In-Reply-To: <20210811142624.618598-1-ming.lei@redhat.com>

On Wed, Aug 11, 2021 at 10:26:24PM +0800, Ming Lei wrote:
> For fixing use-after-free during iterating over requests, we grabbed
> request's refcount before calling ->fn in commit 2e315dc07df0 ("blk-mq:
> grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter").
> Turns out this way may cause kernel panic when iterating over one flush
> request:
> 
> 1) old flush request's tag is just released, and this tag is reused by
> one new request, but ->rqs[] isn't updated yet
> 
> 2) the flush request can be re-used for submitting one new flush command,
> so blk_rq_init() is called at the same time
> 
> 3) meantime blk_mq_queue_tag_busy_iter() is called, and old flush request
> is retrieved from ->rqs[tag]; when blk_mq_put_rq_ref() is called,
> flush_rq->end_io may not be updated yet, so NULL pointer dereference
> is triggered in blk_mq_put_rq_ref().
> 
> Fix the issue by calling refcount_set(&flush_rq->ref, 1) after
> flush_rq->end_io is set. So far the only other caller of blk_rq_init() is
> scsi_ioctl_reset() in which the request doesn't enter block IO stack and
> the request reference count isn't used, so the change is safe.
> 
> Fixes: 2e315dc07df0 ("blk-mq: grab rq->refcount before calling ->fn in
> blk_mq_tagset_busy_iter")
> Reported-by: "Blank-Burian, Markus, Dr." <blankburian@uni-muenster.de>
> Tested-by: "Blank-Burian, Markus, Dr." <blankburian@uni-muenster.de>
> Signed-off-by: Ming Lei <ming.lei@redhat.com>

Hello Jens,

Ping...

Thanks,
Ming


  parent reply	other threads:[~2021-08-17  0:59 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-08-11 14:26 [PATCH] blk-mq: fix kernel panic during iterating over flush request Ming Lei
2021-08-12  8:57 ` Christoph Hellwig
2021-08-12 10:20 ` John Garry
2021-08-12 11:47 ` Xiaoguang Wang
2021-08-12 13:04   ` Ming Lei
2021-08-12 13:19     ` Xiaoguang Wang
2021-08-17  0:58 ` Ming Lei [this message]
2021-08-17 14:33 ` Jens Axboe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=YRsJ00t5XDdlebcW@T590 \
    --to=ming.lei@redhat.com \
    --cc=axboe@kernel.dk \
    --cc=blankburian@uni-muenster.de \
    --cc=bvanassche@acm.org \
    --cc=hch@lst.de \
    --cc=john.garry@huawei.com \
    --cc=linux-block@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.